io.github.LiquiHog/hogswap-mcp
REMOTE · HOGSWAP-V1.LIQUIHOG.DEV · 2 COMPONENTS · SCANNED AUG 17
Pay any Algorand x402 invoice with any asset, plus DEX swap quotes and unsigned builds.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 12 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 406, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1359 tokens (~113/item across 12 items; 12 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management30
- Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · hogswap-v1.liquihog.dev
claude mcp add --transport http liquihog-hogswap-mcp https://hogswap-v1.liquihog.dev/mcp/
[mcp_servers.liquihog-hogswap-mcp] url = "https://hogswap-v1.liquihog.dev/mcp/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"liquihog-hogswap-mcp": {
"type": "remote",
"url": "https://hogswap-v1.liquihog.dev/mcp/",
"enabled": true
}
}
} openclaw mcp add liquihog-hogswap-mcp --url https://hogswap-v1.liquihog.dev/mcp/ --transport streamable-http
mcp_servers:
liquihog-hogswap-mcp:
url: "https://hogswap-v1.liquihog.dev/mcp/" {
"mcpServers": {
"liquihog-hogswap-mcp": {
"type": "http",
"url": "https://hogswap-v1.liquihog.dev/mcp/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 16 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 +1
- Tool “get_quote” rewrote its description, which is the text the model reads security
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- Server version: 0.3.0 → 0.4.0 functional
- 10 Aug 26 +1
- Schema quality: pass → fail ▼ functional
- Server version: 0.2.0 → 0.3.0 functional
- New tool “value_lp_token” functional
- 9 Aug 26 0
- Tool “get_quote” rewrote its description, which is the text the model reads security
- Schema quality: 96 → 107 ▼ functional
- Stability: unverified → 0.03 ▲ functional
- Server version: 0.1.0 → 0.2.0 functional
- New tool “set_watch” functional
- New tool “delete_watch” functional
- New tool “list_watches” functional
- “get_quote” added an optional parameter “max_legs” cosmetic
- 8 Aug 26 54
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 17 Aug 2026 · Probed https://hogswap-v1.liquihog.dev/mcp/
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=liquihog.dev | CN=WE1,O=Google Trust Services,C=US | 30 Jul 2026 | 28 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | 3375d7e671b11f9f0e9f7df88227009f |
| SANs: liquihog.dev, *.liquihog.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of hogswap-v1.liquihog.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| liquihog.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://hogswap-v1.liquihog.dev/mcp/ | Verified | 200 | |
| http (plaintext) | http://hogswap-v1.liquihog.dev/mcp/ | Inconclusive | 406 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
build_swap ~75
Unsigned transaction group for a get_quote quote_id. Sign every txn with your own wallet and submit as one group. NEVER pass mnemonics or private keys to any tool — signing happens in YOUR wallet, never here.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| quote_id | string | yes | – |
| user_address | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
delete_watch ~32
Delete one of your watches by its client_key.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| client_key | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
get_balance ~26
Current HOGSWAP credit balance for your API key.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
get_credit_offer ~79
Create a credit top-up and get the x402 offer (HTTP 402 IS the payment instruction, not an error). Feed accepts[0] straight into pay_x402_invoice (keep the note nonce) to pay with any asset. Credits land ~1 block after payment.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| usdc_micro | integer | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
get_quote ~202
HOGSWAP swap quote across every Algorand DEX. Give amount (exact input) OR amount_out (exact output — minimum input is solved). Base units (µ); asset 0 = ALGO. Returns expected_out, route legs, and a quote_id for build_swap. expected_out is NET of the 5 bps routing fee; passing sender also returns router_fee_* fields and the wallet's HOG discount (hog_discount_pct, 100 = fully waived at 100 HOG). Optional sender enables HOG-holding fee discounts. Optional max_legs (1-16) caps TOTAL route legs, splits included — slightly worse price at size, 404 if nothing fits; forward (amount) quotes only.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | – | – | – |
| amount_out | – | – | – |
| api_key | – | – | – |
| asset_in | integer | yes | – |
| asset_out | integer | yes | – |
| max_legs | – | – | – |
| sender | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
list_payable_assets ~37
Assets accepted as payment inputs for pay_x402_invoice and credit top-ups (price-confidence gated; ALGO and USDC always included).
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
list_watches ~60
List your key's active watches (spec + arming/fired state), quota, and latest event seq. Poll this from MCP to see fires; SSE at GET /watches/stream is the push alternative outside MCP.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
pay_x402_invoice ~179
Pay ANY Algorand-settled x402 invoice with any 1-4 routable assets you hold, even holding none of the demanded asset. Pass the `accepts` entry you picked as `invoice` (keep its note!) plus your inputs (single input with no amount = minimum solved). Returns UNSIGNED groups — sign all in one pass, submit IN ORDER (swap first; its on-chain floor guarantees the payment is funded; holding the asset already = one direct payment). HOGSWAP credit top-up offers feed this verbatim. EVM invoices unsupported (no bridge). NEVER pass mnemonics or private keys to any tool — signing happens in YOUR wallet, never here.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | – | – | – |
| inputs | array | yes | – |
| invoice | object | yes | – |
| user_address | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
register_agent ~78
Self-service HOGSWAP API key, step 1 of 2 — zero human. Returns a challenge; sign its exact bytes with the address's key in YOUR wallet tooling, then call verify_registration. NEVER pass mnemonics or private keys to any tool — signing happens in YOUR wallet, never here.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
set_watch ~268
Register a standing server-side watch (FREE, needs a key; idempotent upsert by client_key — re-registering replaces the watch and resets arming). kind='price': advisory µUSD threshold (asset_id, op gte/lte, threshold_usd_micro). kind='target': size-aware surrogate — would swapping amount_in of asset_in→asset_out deliver ≥ min_out? (margin_bps haircut, default 30; NO quote is run). Edge-triggered one-shot; re-arms after rearm_bps retreat + cooldown_s; ttl_s auto-expiry (default 86400) — refresh by re-upserting. Fires are numbers-only HINTS: re-quote with get_quote. Events push over SSE at GET /watches/stream (outside MCP); from MCP, poll list_watches.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_in | – | – | – |
| api_key | – | – | – |
| asset_id | – | – | – |
| asset_in | – | – | – |
| asset_out | – | – | – |
| client_key | string | yes | – |
| cooldown_s | – | – | – |
| kind | string | yes | – |
| margin_bps | – | – | – |
| min_out | – | – | – |
| op | – | – | – |
| rearm_bps | – | – | – |
| threshold_usd_micro | – | – | – |
| ttl_s | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
value_lp_token ~137
Value a liquidity-provider position. Give the LP token's asset id (free, no key) and optionally `amount` in LP BASE units — what the wallet holds — for its USD value and the redeemable amount of each underlying. Also identifies the issuing pool/DEX (and STAMM tier). Per-unit figures are per WHOLE LP token. Values are a proportional-share redemption at analytics prices: no slippage, no exit fee, NOT a market quote — fields are null rather than guessed when supply or a price is missing, so check before reporting a number.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | – | – | – |
| asset_id | integer | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
verify_registration ~91
Self-service key issuance, step 2 of 2. Returns your hsk_ key ONCE — store it yourself; it is not recoverable and this server does not keep it. Send it on later calls as Authorization: Bearer, X-API-Key, or the api_key argument.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
| challenge | string | yes | – |
| signature_b64 | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.